bq60cmofunul.exe

OOO

The application bq60cmofunul.exe by OOO has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is also typically executed from the user's temporary directory.
Publisher:
IObit  (signed by OOO )

Version:
1.0.0.1

MD5:
6d4e43dd4677c273b1e3e495a796c162

SHA-1:
70c75bb562a49e83dde40193bd4a613478fd6de3

SHA-256:
89f671c30cf0776b1fb05d2a06ec0d98a731d498ff350017765d8d03cef0da5e

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/24/2024 1:48:17 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
17.3.4.12

File size:
535 KB (547,848 bytes)

Product version:
1.0.0.1

Copyright:
Copyright (C) 2015 IObit. All Rights Reserved.

Original file name:
NoteIcon.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\bq60cmofunul.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
8/29/2016 3:00:00 AM

Valid to:
8/30/2017 2:59:59 AM

Subject:
CN="OOO ""INBOKS MARKETING""", O="OOO ""INBOKS MARKETING""", STREET="Bolshoy VO,80", L=Saint Peterburg, S=Saint Peterburg, PostalCode=199106, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00BC4D5469B576BF5C92276B809D9303A6

File PE Metadata
Compilation timestamp:
9/23/2016 6:23:20 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0x7DFF0

Entry point:
55, 8B, EC, 81, EC, A4, 02, 00, 00, 53, 56, 57, C6, 85, 67, FF, FF, FF, 1D, EB, 02, CD, 4F, EB, 02, 87, F7, 68, 13, E0, 47, 00, C3, CD, 83, EB, 01, 55, 8B, C0, 68, 20, E0, 47, 00, C3, 33, DD, 68, 27, E0, 47, 00, C3, 56, EB, 02, 2B, E3, C1, E8, 00, 8B, D2, 8B, 55, 08, 8B, D2, 89, 15, 7C, 40, 48, 00, 89, 2D, 5C, 40, 48, 00, C7, 85, 28, FF, FF, FF, 00, 00, 00, 00, B8, 69, 00, 00, 00, 8B, 0D, 9C, 3F, 48, 00, 66, 89, 01, BA, 6E, 00, 00, 00, A1, 9C, 3F, 48, 00, 66, 89, 50, 02, B9, 66, 00, 00, 00, 8B, 15, 9C, 3F...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
503 KB (515,072 bytes)

Remove bq60cmofunul.exe - Powered by Reason Core Security